CVE-2018-19524

CRITICAL

Shenzhen Skyworth DT741 - DoS/Remote Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-19524. PoCs published by Kaustubh G. Padwad.

AI-analyzed exploit summary This exploit targets a stack-based buffer overflow in the `Web_passwd` function of multiple Shenzhen Skyworth GPON devices, allowing unauthenticated remote code execution or denial of service via a crafted HTTP POST request with an overly long password parameter.

Description

An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1, DT721-cb SDOTBGN1, and DT741-cb SDOTBGN1 devices. A long password to the Web_passwd function allows remote attackers to cause a denial of service (segmentation fault) or achieve unauthenticated remote code execution because of control of registers S0 through S4 and T4 through T7.

Exploits (1)

exploitdb WORKING POC
by Kaustubh G. Padwad · pythondosasp
https://www.exploit-db.com/exploits/46358

This exploit targets a stack-based buffer overflow in the `Web_passwd` function of multiple Shenzhen Skyworth GPON devices, allowing unauthenticated remote code execution or denial of service via a crafted HTTP POST request with an overly long password parameter.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Shenzhen Skyworth DT741, DT721-cb, DT741-cb (multiple versions)
No auth needed
Prerequisites: Network access to the target device · Vulnerable GPON device with exposed web interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_bugtraq
https://seclists.org/bugtraq/2019/Feb/21
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/46358/
Various Sources x_refsource_misc
https://s3curityb3ast.github.io/KSA-Dev-001.md
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2019/Feb/30

Scores

CVSS v3 9.8
EPSS 0.5052
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (3)
skyworthdigital/dt721-cb_firmware sdotbgn1
skyworthdigital/dt740_firmware sdotbgn1
skyworthdigital/dt741-cb_firmware sdotbgn1
Published Mar 21, 2019
Tracked Since Feb 18, 2026